CyberRota Analysis
AI-GeneratedEclipse Arrowhead versions 5.0.0 to 5.2.1 are vulnerable due to a flaw in the management-authorization gate that allows unauthenticated users to bypass security checks on REST endpoints. This vulnerability enables attackers to exploit encoded URLs to access sensitive management operations, potentially leading to full administrative control over the system. Organizations using affected versions should prioritize immediate patching to mitigate the risk of unauthorized access and administrative takeover.
Original NVD Description
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.